CompTIA Network+ (N10-009)Network SecurityHard
A penetration tester repeatedly sends spoofed 802.11 management frames to a client connected to the corporate WPA2 access point, forcing the client to disconnect. Moments later, the client automatically reconnects, and the tester captures the resulting four-way handshake for offline password cracking. Which technique did the tester use to force the reconnection?
- AEvil twin
- BDeauthentication attack
- CVLAN hopping
- DARP spoofing
Show answer & explanationAnswer & explanation
Correct answer: B. Deauthentication attack
A deauthentication attack sends forged 802.11 deauth management frames to disconnect a client from its AP, forcing a reconnection that can be captured to obtain the WPA/WPA2 handshake for offline cracking. Evil twin is a fake AP impersonation, ARP spoofing targets IP-to-MAC mappings, and VLAN hopping targets Layer 2 segmentation—none directly force a Wi-Fi client to disconnect via management frames.
Why the other options are wrong
- A. Evil twin is an impersonating rogue AP, not a frame-based disconnect technique.
- C. VLAN hopping exploits switch tagging, unrelated to wireless client disconnection.
- D. ARP spoofing manipulates ARP caches on wired/wireless LANs, not 802.11 management frames.
Deauthentication Attack
A wireless attack that sends forged 802.11 deauthentication management frames to disconnect a client from its access point, often used to force a reconnection and capture the WPA handshake.
- Exploits unauthenticated 802.11 management frames
- Common precursor to WPA2 handshake capture for offline cracking
- Mitigated by 802.11w (Management Frame Protection)
Memory trick: Kick them off, catch them coming back on.